Thanks for your help. The first text file is the OTL file followed by the Extras text file
OTL logfile created on: 4/6/2011 8:52:35 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Program Files\DDS
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,022.00 Mb Total Physical Memory | 244.00 Mb Available Physical Memory | 24.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 4096 4096 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.46 Gb Total Space | 23.97 Gb Free Space | 33.55% Space Free | Partition Type: NTFS
Computer Name: CHRISCOMPUTER | User Name: Venissa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Program Files\DDS\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe (SlySoft, Inc.)
PRC - C:\WINDOWS\system32\java.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe ( )
PRC - C:\Program Files\Norton 360\Engine\4.3.0.5\ccsvchst.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation)
PRC - C:\Program Files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe (Linksys LLC - A Division of Cisco Systems)
PRC - C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ewido anti-spyware 4.0\guard.exe (Anti-Malware Development a.s.)
PRC - C:\Program Files\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe (InstallShield Software Corporation)
PRC - C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
PRC - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe (Executive Software International, Inc.)
========== Modules (SafeList) ==========
MOD - C:\Program Files\DDS\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Norton 360\Engine\4.3.0.5\asoehook.dll (Symantec Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\SlySoft\AnyDVD\ADvdDiscHlp.dll (SlySoft, Inc.)
MOD - C:\Program Files\Norton 360\Engine\4.3.0.5\microsoft.vc90.crt\msvcr90.dll (Microsoft Corporation)
MOD - C:\Program Files\Norton 360\Engine\4.3.0.5\microsoft.vc90.crt\msvcp90.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (N360) – C:\Program Files\Norton 360\Engine\4.3.0.5\ccSvcHst.exe (Symantec Corporation)
SRV - (ZuneWlanCfgSvc) – C:\WINDOWS\system32\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc) – c:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (ZuneBusEnum) – C:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation)
SRV - (LinksysUpdater) – C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe ()
SRV - (nmservice) – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Pure Networks, Inc.)
SRV - (SoundMovieServer) – C:\WINDOWS\System32\snmvtsvc.exe (SoundMovieServer)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (ewido anti-spyware 4.0 guard) – C:\Program Files\ewido anti-spyware 4.0\guard.exe (Anti-Malware Development a.s.)
SRV - (Diskeeper) – C:\Program Files\Executive Software\DiskeeperLite\DKService.exe (Executive Software International, Inc.)
========== Driver Services (SafeList) ==========
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20110406.003\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20110406.003\NAVENG.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\IPSDefs\20110405.001\IDSXpx86.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\BASHDefs\20110309.001\BHDrvx86.sys (Symantec Corporation)
DRV - (AnyDVD) – C:\WINDOWS\system32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\N360\0403000.005\SYMTDI.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\0403000.005\Ironx86.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0403000.005\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\N360\0403000.005\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\N360\0403000.005\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) – C:\WINDOWS\system32\drivers\N360\0403000.005\ccHPx86.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\0403000.005\SYMDS.SYS (Symantec Corporation)
DRV - (pnarp) – C:\WINDOWS\system32\drivers\pnarp.sys (Pure Networks, Inc.)
DRV - (purendis) – C:\WINDOWS\system32\drivers\purendis.sys (Pure Networks, Inc.)
DRV - (MusCVideo32) – C:\WINDOWS\system32\drivers\MusCVideo32.sys (Windows ® 2000 DDK provider)
DRV - (MusCDriverV32) – C:\WINDOWS\system32\drivers\MusCDriverV32.sys (Windows ® 2000/XP)
DRV - (tmcomm) – C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (dsunidrv) – C:\WINDOWS\system32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (WinUSB) – C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (ewido anti-spyware 4.0 driver) – C:\Program Files\ewido anti-spyware 4.0\guard.sys ()
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (WinDriver6) – C:\WINDOWS\system32\drivers\windrvr6.sys (Jungo)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.raidernews.com/x/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 78 F8 C5 F7 29 0E CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "
http://www.iwon.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\IPSFFPlgn\ [2010/05/25 18:45:07 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\coFFPlgn\ [2010/05/10 23:31:53 | 000,000,000 | —D | M]
[2009/07/25 18:47:52 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Venissa\Application Data\Mozilla\Extensions
[2010/12/16 22:48:51 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Venissa\Application Data\Mozilla\Firefox\Profiles\czrif6vu.default\extensions
[2010/10/01 20:52:52 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Venissa\Application Data\Mozilla\Firefox\Profiles\czrif6vu.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/05/10 23:31:53 | 000,000,000 | —D | M] (Norton Toolbar) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\COFFPLGN
[2010/05/25 18:45:07 | 000,000,000 | —D | M] (Norton IPS) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\IPSFFPLGN
[2009/07/26 21:54:34 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
O1 HOSTS File: ([2011/04/04 20:00:04 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\4.3.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [LELA] C:\Program Files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe (Linksys LLC - A Division of Cisco Systems)
O4 - HKLM..\Run: [Name of App] C:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe ( )
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKCU..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe (SlySoft, Inc.)
O4 - HKCU..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil10l_ActiveX.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\AllMusicConverter\YouTubeRipper.dll ()
O9 - Extra 'Tools' menuitem : Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\AllMusicConverter\YouTubeRipper.dll ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe (PokerStars)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: army.mil ([www.aimsrdl.atsc] https in Trusted sites)
O15 - HKCU\..Trusted Domains: ati.com ([support] https in Trusted sites)
O15 - HKCU\..Trusted Domains: google.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O15 - HKCU\..Trusted Domains: iwon.com ([home] http in Trusted sites)
O15 - HKCU\..Trusted Domains: iwon.com ([news1] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([support] http in Trusted sites)
O15 - HKCU\..Trusted Domains: pokerstars.net ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: slysoft.com ([www.static] http in Trusted sites)
O15 - HKCU\..Trusted Domains: tsp.gov ([www] http in Trusted sites)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4}
http://download.microsoft.com/download/0/f…tualEarth3D.cab (Reg Error: Key error.)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab (CKAVWebScan Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/3/9…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874}
http://www.worldwinner.com/games/v50/tpir/tpir.cab (TPIR Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258}
http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} https://disneyblast.go.com/v3/setup/activex…wareControl.cab (Walt Disney Internet Group Hardware Control)
O16 - DPF: {38F5F92F-BD40-40DF-A569-6C1FCB638190}
http://www.powerleap.com/cab_files/InSPECS3_0.cab (InSPECS3_0 Control)
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} http://disney.go.com/pirates/online/testAc…OnlineGames.cab (Disney Online Games ActiveX Control)
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab (Symantec Script Runner Class)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase5036.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdat…b?1144893173093 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab (Groove Control)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {924B4927-D3BA-41EA-9F7E-8A89194AB3AC} http://panda-plugin.disney.go.com/plugin/w…/p3dactivex.cab (P3DActiveX Control)
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F}
http://www.worldwinner.com/games/v57/wof/wof.cab (WoF Control)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3}
https://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe (Virtools WebPlayer Class)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C}
http://www.gamehouse.com/realarcade-webgam…WeddingDash.cab (CPlayFirstWeddingDashControl Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp3.dll (Pure Networks, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 () - C:\Program Files\Internet Explorer\wonojudix.html
O24 - Desktop Components:1 () - C:\Program Files\Online Services\teleg.html
O24 - Desktop Components:2 (My Current Home Page) - About:Home
O24 - Desktop Components:3 (Microsoft Update) -
http://www.update.microsoft.com/microsoftu…e.aspx?ln=en-us
O24 - Desktop WallPaper: C:\WINDOWS\Dell.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Dell.bmp
O28 - HKLM ShellExecuteHooks: {57B86673-276A-48B2-BAE7-C6DBB3020EB8} - C:\Program Files\ewido anti-spyware 4.0\shellexecutehook.dll (Anti-Malware Development a.s.)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll ()
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56871556046913536)
========== Files/Folders - Created Within 30 Days ==========
[2011/04/05 19:28:48 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/04/05 19:01:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Venissa\Application Data\Malwarebytes
[2011/04/05 19:01:01 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/04/05 19:00:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/04/05 19:00:54 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/04/05 19:00:54 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/04/04 19:40:23 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/04/04 19:34:17 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/04/04 19:34:17 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/04/04 19:34:17 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/04/04 19:34:17 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/04/04 19:33:51 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/04/04 19:33:12 | 000,000,000 | —D | C] – C:\Qoobox
[2011/04/03 14:09:23 | 000,000,000 | —D | C] – C:\Program Files\DDS
[2011/04/01 19:18:38 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/04/01 19:18:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Venissa\Start Menu\Programs\HiJackThis
[2011/03/23 18:39:24 | 001,531,392 | —- | C] (Toshiba Samsung Storage Technology Corporation) – C:\Documents and Settings\Venissa\Application Data\tsdnwin.dll
[2011/03/23 18:20:33 | 000,000,000 | —D | C] – C:\Program Files\SAMSUNG
[2011/03/23 18:20:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ODD Firmware LiveUpdate
[2011/03/23 18:11:44 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Essentials
[2011/03/23 18:00:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Nero
[2011/03/23 18:00:31 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Ahead
[2011/03/22 21:00:48 | 000,000,000 | —D | C] – C:\DVD_VIDEO_RECORDER
[2011/03/13 11:42:36 | 000,000,000 | —D | C] – C:\Risk2
[2007/08/04 19:33:54 | 000,774,144 | —- | C] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[10 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/04/06 20:02:01 | 000,000,258 | —- | M] () – C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2011/04/06 17:29:43 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/04/06 17:26:46 | 000,000,456 | —- | M] () – C:\Documents and Settings\Venissa\Application Data\SamsungLiveUpdateConfig.ini
[2011/04/06 17:23:51 | 000,235,289 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2011/04/06 17:22:28 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/06 17:21:25 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/04/06 17:21:18 | 1071,697,920 | -HS- | M] () – C:\hiberfil.sys
[2011/04/05 19:01:02 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/04 20:00:15 | 000,000,680 | —- | M] () – C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Venissa.job
[2011/04/04 20:00:04 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/04/04 19:40:31 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2011/04/03 13:38:26 | 000,002,451 | —- | M] () – C:\Documents and Settings\Venissa\Desktop\HiJackThis.lnk
[2011/04/01 18:25:29 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/04/01 06:46:40 | 000,002,497 | —- | M] () – C:\Documents and Settings\Venissa\Desktop\Microsoft Office Word 2003.lnk
[2011/03/27 21:35:38 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/03/26 15:20:08 | 000,000,136 | —- | M] () – C:\Documents and Settings\Venissa\default.pls
[2011/03/23 18:40:44 | 001,531,392 | —- | M] (Toshiba Samsung Storage Technology Corporation) – C:\Documents and Settings\Venissa\Application Data\tsdnwin.dll
[2011/03/23 18:10:45 | 000,002,379 | —- | M] () – C:\Documents and Settings\Venissa\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart Essentials.lnk
[2011/03/23 18:10:45 | 000,002,279 | —- | M] () – C:\Documents and Settings\Venissa\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero Home Essentials SE.lnk
[2011/03/23 18:10:44 | 000,002,361 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Nero StartSmart Essentials.lnk
[2011/03/23 18:10:44 | 000,001,879 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Nero Online Upgrade.lnk
[2011/03/23 18:10:42 | 000,002,261 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Nero Home Essentials SE.lnk
[2011/03/21 17:54:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/03/15 23:14:01 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/03/15 19:24:11 | 000,002,521 | —- | M] () – C:\Documents and Settings\Venissa\Desktop\Microsoft Office Outlook 2003.lnk
[2011/03/13 09:51:46 | 000,445,836 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/03/13 09:51:46 | 000,073,042 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/03/13 00:15:18 | 000,000,754 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AnyDVD.lnk
[2011/03/12 09:32:40 | 000,000,792 | —- | M] () – C:\Documents and Settings\Venissa\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[10 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/04/05 19:01:01 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/04 19:40:31 | 000,000,211 | —- | C] () – C:\Boot.bak
[2011/04/04 19:40:27 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/04/04 19:34:17 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/04/04 19:34:17 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/04/04 19:34:17 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/04/04 19:34:17 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/04/04 19:34:17 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/04/01 19:18:38 | 000,002,451 | —- | C] () – C:\Documents and Settings\Venissa\Desktop\HiJackThis.lnk
[2011/03/23 18:21:13 | 000,000,456 | —- | C] () – C:\Documents and Settings\Venissa\Application Data\SamsungLiveUpdateConfig.ini
[2011/03/23 18:10:45 | 000,002,379 | —- | C] () – C:\Documents and Settings\Venissa\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart Essentials.lnk
[2011/03/23 18:10:44 | 000,002,279 | —- | C] () – C:\Documents and Settings\Venissa\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero Home Essentials SE.lnk
[2011/03/23 18:10:44 | 000,001,879 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Nero Online Upgrade.lnk
[2011/03/23 18:10:42 | 000,002,361 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Nero StartSmart Essentials.lnk
[2011/03/23 18:10:40 | 000,002,261 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Nero Home Essentials SE.lnk
[2011/03/06 02:34:23 | 000,256,392 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/02/21 18:35:04 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2011/02/07 18:47:03 | 000,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2010/10/05 02:04:45 | 000,015,880 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2010/01/09 20:46:00 | 000,103,535 | —- | C] () – C:\WINDOWS\hpoins04.dat
[2010/01/09 20:46:00 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat
[2009/12/26 20:51:36 | 000,078,172 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/07/20 11:58:39 | 001,580,550 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2009/06/10 09:29:34 | 001,724,416 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2009/06/10 09:29:34 | 001,657,376 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2009/06/10 09:29:34 | 001,101,824 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2009/06/10 09:29:34 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2009/06/10 09:29:34 | 000,449,056 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2009/06/10 09:29:34 | 000,436,768 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2009/06/10 09:29:32 | 001,507,328 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2008/07/16 18:56:28 | 003,049,984 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2008/07/16 18:56:28 | 000,404,480 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2008/07/16 18:56:28 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2008/07/16 18:56:28 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2008/06/21 20:49:58 | 000,000,040 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2008/05/31 07:25:11 | 000,000,000 | —- | C] () – C:\Program Files\temp01
[2008/02/18 18:18:17 | 000,001,273 | —- | C] () – C:\WINDOWS\checkip.dat
[2007/06/19 21:52:14 | 000,002,875 | —- | C] () – C:\WINDOWS\ACROREAD.INI
[2007/04/11 16:04:25 | 000,000,000 | —- | C] () – C:\WINDOWS\game.INI
[2007/03/22 18:43:18 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2007/02/19 23:02:43 | 000,000,551 | —- | C] () – C:\Documents and Settings\Venissa\Application Data\AutoGK.ini
[2007/02/19 22:24:16 | 000,043,602 | —- | C] () – C:\WINDOWS\System32\xvid-uninstall.exe
[2007/02/19 15:17:38 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/02/19 15:13:27 | 000,002,236 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/12/28 22:54:05 | 000,000,294 | —- | C] () – C:\WINDOWS\EReg077.dat
[2006/12/08 08:50:14 | 000,217,088 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2006/12/08 08:47:54 | 001,159,168 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2006/12/06 20:04:12 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/11/11 15:21:57 | 000,038,912 | —- | C] () – C:\Documents and Settings\Venissa\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/09/14 21:51:33 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2006/08/15 19:30:43 | 000,061,678 | —- | C] () – C:\Documents and Settings\Venissa\Application Data\PFP120JPR.{PB
[2006/08/15 19:30:43 | 000,012,358 | —- | C] () – C:\Documents and Settings\Venissa\Application Data\PFP120JCM.{PB
[2006/06/21 18:15:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ATIMMC.INI
[2006/05/18 20:05:03 | 000,000,130 | —- | C] () – C:\Documents and Settings\Venissa\Local Settings\Application Data\fusioncache.dat
[2006/04/12 17:27:14 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/03/13 21:17:18 | 000,000,124 | —- | C] () – C:\WINDOWS\POOHRTR.INI
[2006/03/13 21:17:18 | 000,000,124 | —- | C] () – C:\WINDOWS\POOHRFM.INI
[2006/02/25 21:38:54 | 000,000,139 | —- | C] () – C:\WINDOWS\chmpchss.INI
[2006/02/23 21:55:52 | 000,000,119 | —- | C] () – C:\WINDOWS\PINOCHLE.INI
[2006/02/20 16:23:37 | 000,000,212 | —- | C] () – C:\WINDOWS\CRIBBAGE.INI
[2006/02/20 16:22:49 | 000,003,350 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/02/20 16:22:49 | 000,000,056 | RHS- | C] () – C:\WINDOWS\System32\917E16CFEB.sys
[2006/01/29 11:36:21 | 000,109,056 | —- | C] () – C:\WINDOWS\System32\UNINSTAL.EXE
[2006/01/29 11:36:07 | 000,982,016 | R— | C] () – C:\WINDOWS\System32\RGT002.DLL
[2006/01/20 18:05:39 | 000,001,819 | —- | C] () – C:\WINDOWS\disney.ini
[2005/12/28 17:17:35 | 000,000,016 | —- | C] () – C:\WINDOWS\ka.ini
[2005/12/23 20:07:59 | 000,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2005/12/19 23:00:38 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/12/19 22:57:39 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2005/12/19 22:49:43 | 000,000,686 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/12/19 22:48:10 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2005/12/19 22:27:26 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2005/12/19 22:27:06 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2005/12/19 22:27:04 | 000,000,392 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/05/04 20:54:50 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/11/30 05:10:00 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\besch.exe
[2004/11/30 05:10:00 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\besched.dll
[2004/08/10 15:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 15:07:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/10 15:02:15 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 14:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 14:57:15 | 000,334,664 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 14:51:35 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2004/08/10 14:51:35 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2004/08/10 14:51:35 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2004/08/10 14:51:35 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2004/08/10 14:51:35 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2004/08/10 14:51:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 14:51:20 | 000,445,836 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 14:51:20 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 14:51:20 | 000,073,042 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 14:51:20 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 14:51:18 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/10 14:51:17 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/10 14:51:16 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/10 14:51:12 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 14:51:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 14:51:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 14:50:56 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2003/10/02 02:00:00 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\lockout.dll
[2003/10/02 02:00:00 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\lockres.dll
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2000/09/08 17:53:50 | 000,073,839 | —- | C] () – C:\WINDOWS\System32\KodakOneTouch.dll
[2000/04/25 13:58:08 | 000,047,104 | —- | C] () – C:\WINDOWS\System32\Wrkgadm.exe
========== LOP Check ==========
[2009/01/20 15:22:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\eGames
[2008/06/13 19:32:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HipSoft
[2010/11/14 20:30:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iWin Games
[2008/06/07 22:34:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lifetime
[2008/06/24 01:21:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2009/07/22 23:24:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Linksys
[2008/12/14 18:42:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
[2009/12/17 01:11:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCSettings
[2008/12/14 12:55:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2008/03/16 12:02:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Purple Ghost Software, Inc
[2008/06/21 20:50:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SlySoft
[2008/06/15 16:30:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spiralfrog
[2009/11/01 17:12:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/01/26 16:32:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/07/21 20:00:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2007/04/20 07:39:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\YAHOO
[2007/09/23 15:06:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Zylom
[2009/11/29 12:59:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/10/02 17:50:54 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}
[2008/07/19 08:25:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\Any Video Converter
[2008/03/16 12:39:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\ASCOMP Software
[2007/04/14 16:48:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\Azureus
[2009/01/20 15:22:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\eGames
[2008/07/26 00:11:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\Feedreader
[2009/01/21 09:42:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\GameHouse
[2009/06/10 16:20:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\Gamelab
[2009/01/20 10:56:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\GOL_byHasbro
[2008/06/08 12:56:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\Home Sweet Home
[2008/11/28 13:40:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\Home Sweet Home 2
[2008/06/29 23:01:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\Ice Age 2
[2008/06/11 14:43:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\iWin
[2006/11/11 14:14:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\Leadertech
[2007/08/05 21:56:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\My Games
[2006/12/06 20:31:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\OfficeUpdate12
[2008/11/28 14:38:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\PetShowCraze
[2008/12/14 12:55:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\PlayFirst
[2008/03/16 12:02:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\Purple Ghost Software, Inc
[2006/08/03 16:16:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\System Restore
[2010/09/24 07:11:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\Tific
[2010/02/09 13:24:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\Uniblue
[2007/01/26 16:32:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\Viewpoint
[2011/03/27 21:40:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\WeatherBug
[2006/05/21 16:48:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Venissa\Application Data\X10 Commander
[2011/04/06 17:29:43 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2011/04/06 20:02:01 | 000,000,258 | —- | M] () – C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/04/06 17:21:16 | 000,052,835 | —- | M] () – C:\aaw7boot.log
[2010/02/09 14:23:04 | 000,000,211 | —- | M] () – C:\Boot.bak
[2011/04/04 19:40:31 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2011/04/04 20:18:25 | 000,018,706 | —- | M] () – C:\ComboFix.txt
[2008/07/16 18:58:33 | 000,001,382 | —- | M] () – C:\Cucu_Video_log.txt
[2005/12/19 22:31:34 | 000,005,173 | RH– | M] () – C:\dell.sdr
[2008/11/20 17:22:27 | 000,000,097 | —- | M] () – C:\DownloadLog.txt
[2006/07/21 08:15:59 | 000,000,001 | —- | M] () – C:\DXOkay.bin
[2007/02/25 16:33:02 | 000,000,154 | —- | M] () – C:\fairuse.log
[2008/04/06 09:18:59 | 000,000,016 | —- | M] () – C:\h.txt
[2011/04/06 17:21:18 | 1071,697,920 | -HS- | M] () – C:\hiberfil.sys
[2006/05/12 17:03:46 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2006/05/19 23:25:58 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/02/18 20:25:04 | 000,000,125 | —- | M] () – C:\ioSpecial.ini
[2011/02/21 19:34:54 | 000,000,449 | —- | M] () – C:\mmcInst.log
[2006/05/19 23:25:58 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/07/13 09:48:46 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/04/06 17:21:17 | 4293,918,720 | -HS- | M] () – C:\pagefile.sys
[2008/11/20 17:23:07 | 000,003,219 | —- | M] () – C:\playground.log
[2010/10/08 15:36:33 | 000,008,427 | —- | M] () – C:\THE_KARATE_KID.MDS
[2009/06/14 21:16:29 | 000,000,190 | —- | M] () – C:\wizard.txt
[2009/07/25 17:03:59 | 000,000,150 | —- | M] () – C:\YServer.txt
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2004/08/10 15:03:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 14:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2007/08/04 19:33:41 | 000,774,144 | —- | M] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll
[2008/05/31 07:25:11 | 000,000,000 | —- | M] () – C:\Program Files\temp01
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/08/10 14:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/08/10 14:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/08/10 14:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/07/13 09:57:17 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/07/13 10:06:48 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Venissa\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/10 15:08:38 | 000,000,079 | —- | M] () – C:\Documents and Settings\Venissa\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2006/05/18 19:58:33 | 035,935,472 | —- | M] (ATI Technologies Inc.) – C:\Documents and Settings\Venissa\Desktop\6-4_xp-2k_dd_ccc_wdm_enu_31959.exe
[2007/06/08 09:16:46 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Venissa\Desktop\ATF-Cleaner.exe
[2006/05/18 19:32:34 | 023,510,720 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Venissa\Desktop\dotnetfx.exe
[2010/09/23 22:43:18 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Venissa\Desktop\setup-spybotsd162.exe
[2008/10/11 12:39:25 | 014,968,808 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Venissa\Desktop\spybotsd160.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-24 11:26:32
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 163 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5A823589
@Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F50F1555
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EDC284A8
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4363DE71
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6BD304B9
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3BAD65EA
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:816B2485
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:43E95997
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:81653DC8
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:067BF339
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:33384BC0
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D2A5A561
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1037D53D
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E4FCDFD9
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C39E55C5
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1740DC47
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D7DA89B1
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CEE4A457
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:22741C1F
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:80B291A7
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:483AC68A
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D387C245
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CF33321C
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:48F5D95B
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FC60E0F8
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8AA99C0C
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:63F8EC77
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:89C6F032
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7FB468B7
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1A347EE4
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:98AE08EA
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BE6DC701
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:708BB0FA
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A468A21E
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AADC76BA
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9EC86225
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:57EE48CA
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4E6B8D68
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4AD2C54D
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3A6BC948
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D8134D8F
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B6285236
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A93CCA6B
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4EF94CF3
< End of report >
OTL Extras logfile created on: 4/6/2011 8:52:35 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Program Files\DDS
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,022.00 Mb Total Physical Memory | 244.00 Mb Available Physical Memory | 24.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 4096 4096 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.46 Gb Total Space | 23.97 Gb Free Space | 33.55% Space Free | Partition Type: NTFS
Computer Name: CHRISCOMPUTER | User Name: Venissa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"67:UDP" = 67:UDP:*:Enabled:DHCP Discovery Service
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare – ()
"C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe" = C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe:LocalSubNet:Enabled:Pure Networks Platform Service – (Pure Networks, Inc.)
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server – (Intuit Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier
"{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}" = Zune Language Pack (FR)
"{03EDED24-8375-407D-A721-4643D9768BE1}" = kgchlwn
"{05BDC796-3451-4F81-B91D-E98F7ADA76C2}" = TurboTax 2010 WinPerTaxSupport
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{073F22CE-9A5B-4A40-A604-C7270AC6BF34}" = ESSSONIC
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{117CD9C0-0F15-4633-93D7-F957B50535A5}" = Popup Blocker (Windows Live Toolbar)
"{11F3F858-4131-4FFA-A560-3FE282933B6E}" = kgchday
"{11F5D779-7BD9-465A-BBC4-10701386BCB9}" = FW LiveUpdate
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{14291118-0C19-45EA-A4FA-5C1C0F5FDE09}" = Primo
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{154508C0-07C5-4659-A7A0-E49968750D21}" = HLPPDOCK
"{1707BF02-0F5C-4A6C-8F17-053BB73E443F}" = Tabbed Browsing (Windows Live Toolbar)
"{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}" = Intel® PROSet for Wired Connections
"{1A6A6531-08FC-47AD-BAC4-C41497E71033}" = Nero 7 Essentials
"{1C118C8D-DB12-4DBE-8F0A-2FAE4393C86E}" = Mathathon
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 24
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{3727B920-F5A3-46A4-AC02-94F421A039C7}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{3782EC09-4000-475E-8A59-9CABD6F03B4C}" = TurboTax 2010 WinPerFedFormset
"{38024121-D084-4E7D-B1A2-1A04CB5C4CF3}" = Windows Live Toolbar Feed Detector (Windows Live Toolbar)
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{38D097C0-EAA2-012B-ADC2-000000000000}" = TurboTax 2009 wksiper
"{39003340-EAA2-012B-ADCD-000000000000}" = TurboTax 2009 wkyiper
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353}" = OTtBPSDK
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{49672EC2-171B-47B4-8CE7-50D7806360D7}" = Windows Live Sign-in Assistant
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F2FCCCF-29F3-44B9-886F-6D16F8417522}" = TurboTax 2010 wrapper
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{637099FB-45FD-4BC7-9651-6FB540DBB749}" = Roxio Backup MyPC
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{693C08A7-9E76-43FF-B11E-9A58175474C4}" = kgckids
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}" = Digital Content Portal
"{6E179C77-7335-458D-9537-4F4EAC0181ED}" = Photo Click
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}" = EarthLink setup files
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7A3F0566-5E05-4919-9C98-456F6B5CF831}" = Get High Speed Internet!
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{7FE3214C-283E-40C6-A8D5-CB773110090C}" = Linksys EasyLink Advisor
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch® Jukebox
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{87843A41-7808-4F2E-B13F-25C1E67CF2FD}" = ESShelp
"{888FFC82-688D-46AB-A776-B417885432B6}" = Zune
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8A62A068-3FD6-495A-9F66-26FE94F32EC9}" = Rhapsody Player Engine
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8A8664E1-84C8-4936-891C-BC1F07797549}" = kgcvday
"{8A9B8148-DDD7-448F-BD6C-358386D32354}" = Corel Photo Album 6
"{8BBF6DFD-0AD9-43A7-9FBD-BF065E3866AF}" = URGE
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95FC661A-A0C5-4B18-92CE-90347DA79CC9}" = Smart Menus (Windows Live Toolbar)
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9BD54685-1496-46A5-AB62-357CD140ED8B}" = kgcinvt
"{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}" = ESScore
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = iSEEK AnswerWorks English Runtime
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.2
"{A1588373-1D86-4D44-86C9-78ABD190F9CC}" = kgcmove
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A3F60446-48FB-48A8-B5FC-BB3430AEF806}" = Diskeeper Lite
"{A40D6757-B145-4FE7-B694-89180A9F3F64}" = Windows Live Outlook Toolbar (Windows Live Toolbar)
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{A525E00B-6609-442E-9DCD-64453C233E8D}" = TurboTax 2010 WinPerReleaseEngine
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{A683A2C0-821C-486F-858C-FA634DB5E864}" = EducateU
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes
"{A92A4DB0-CD37-42D1-BE1D-603D53C24328}" = Intel® Processor ID Utility
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC0EE5B0-A8FB-4D0A-AF03-2EDC518F841B}" = Dell Media Experience
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{AEE512CE-2D5B-4E87-B729-2FBD7718EED7}" = TurboTax 2010 wksiper
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B395BC1D-CC06-425E-9049-4CD985EFF004}" = LightScribe 1.8.15.1
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}" = KSU
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}" = WebEx Support Manager for Internet Explorer
"{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0EE2F91-CC20-426F-A4D5-7FFE54E55015}" = TurboTax 2010 wkyiper
"{D1973749-F5E7-40EB-B528-F2B78685B9FF}" = essvcpt
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"{DA0FFF7B-DA9D-46A2-A329-87804ECA58EA}" = Windows Live Toolbar
"{DABF43D9-1104-4764-927B-5BED1274A3B0}" = Runtime
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{DF821FC5-C198-452B-A0D4-82433EFEAE9B}" = OneCare Advisor (Windows Live Toolbar)
"{E18B549C-5D15-45DA-8D8F-8FD2BD946344}" = kgcbaby
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{ECDA9BD9-A54E-462A-8191-A2B569D9AB34}" = Map Button (Windows Live Toolbar)
"{EE4ACABF-531E-419A-9225-B8E0FA4955AF}" = Zune Language Pack (ES)
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}" = kgcbase
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F5AF5CDA-76FC-4794-9F28-09B6D54E7431}" = Form Fill (Windows Live Toolbar)
"{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}" = OTtBP
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FDF9943A-3D5C-46B3-9679-586BD237DDEE}" = SKIN0001
"3DGroove" = OTOY
"Ad-Aware" = Ad-Aware
"Adobe Acrobat Reader 3.01" = Adobe Acrobat Reader 3.01
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"AllMusicConverter_is1" = AllMusicConverter 3.3.3
"Anapod CopyGear" = Anapod CopyGear (remove only)
"AnyDVD" = AnyDVD
"AudibleManager" = AudibleManager
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"DIG Game Manager" = DIG Game Manager
"Disney Toontown Online" = Disney Toontown Online
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"ESET Online Scanner" = ESET Online Scanner v3
"ewidoantispyware4" = ewido anti-spyware 4.0
"FeedReader_is1" = FeedReader
"HP Photo & Imaging" = HP Image Zone 4.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"InstallShield_{7FE3214C-283E-40C6-A8D5-CB773110090C}" = Linksys EasyLink Advisor
"InstallShield_{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO
"iPod To Computer Transfer_is1" = iPod To Computer Transfer 3.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"MyDefrag v4.3.1_is1" = MyDefrag v4.3.1
"N360" = Norton 360
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PokerStars.net" = PokerStars.net
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0" = RealPlayer
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4
"SystemRequirementsLab" = System Requirements Lab
"TurboTax 2009" = TurboTax 2009
"TurboTax 2010" = TurboTax 2010
"TVUPlayer" = TVUPlayer 2.2.0
"VB Runtime" = VB Runtime
"ViewpointMediaPlayer" = Viewpoint Media Player
"Virtools3DLifePlayer" = Virtools 3D Life Player
"VLC media player" = VLC media player 1.1.0-pre1
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"WeatherBug" = WeatherBug
"WIC" = Windows Imaging Component
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Live Toolbar" = Windows Live Toolbar
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"winusb0100" = Microsoft WinUsb 1.0
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01009" = Microsoft User-Mode Driver Framework Feature Pack 1.9
"XviD MPEG4 Video Codec" = XviD MPEG4 Video Codec (remove only)
"Zune" = Zune
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 4/1/2011 9:03:31 PM | Computer Name = CHRISCOMPUTER | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module flash10l.ocx, version 10.1.102.64, fault address 0x001373d9.
Error - 4/4/2011 7:04:39 PM | Computer Name = CHRISCOMPUTER | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 4/4/2011 7:43:17 PM | Computer Name = CHRISCOMPUTER | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module unknown, version 0.0.0.0, fault address 0x715b9e59.
Error - 4/4/2011 7:44:35 PM | Computer Name = CHRISCOMPUTER | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module unknown, version 0.0.0.0, fault address 0x715b9e59.
Error - 4/4/2011 8:06:34 PM | Computer Name = CHRISCOMPUTER | Source = Application Hang | ID = 1002
Description = Hanging application Weather.exe, version 6.7.0.10, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 4/4/2011 8:07:04 PM | Computer Name = CHRISCOMPUTER | Source = Application Hang | ID = 1002
Description = Hanging application Weather.exe, version 6.7.0.10, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 4/5/2011 5:33:42 PM | Computer Name = CHRISCOMPUTER | Source = Application Hang | ID = 1002
Description = Hanging application Weather.exe, version 6.7.0.10, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 4/5/2011 5:34:54 PM | Computer Name = CHRISCOMPUTER | Source = Application Hang | ID = 1002
Description = Hanging application Weather.exe, version 6.7.0.10, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 4/5/2011 5:34:55 PM | Computer Name = CHRISCOMPUTER | Source = Application Hang | ID = 1002
Description = Hanging application Weather.exe, version 6.7.0.10, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 4/5/2011 11:40:55 PM | Computer Name = CHRISCOMPUTER | Source = Application Hang | ID = 1002
Description = Hanging application mbam.exe, version 1.50.1.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
[ System Events ]
Error - 3/23/2011 8:04:57 PM | Computer Name = CHRISCOMPUTER | Source = Cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom3.
Error - 3/23/2011 8:05:05 PM | Computer Name = CHRISCOMPUTER | Source = Cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom3.
Error - 3/23/2011 8:05:14 PM | Computer Name = CHRISCOMPUTER | Source = Cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom3.
Error - 3/23/2011 8:05:23 PM | Computer Name = CHRISCOMPUTER | Source = Cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom3.
Error - 3/23/2011 8:05:32 PM | Computer Name = CHRISCOMPUTER | Source = Cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom3.
Error - 3/23/2011 8:05:42 PM | Computer Name = CHRISCOMPUTER | Source = Cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom3.
Error - 3/24/2011 2:49:27 PM | Computer Name = CHRISCOMPUTER | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the N360 service.
Error - 3/24/2011 2:49:56 PM | Computer Name = CHRISCOMPUTER | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the nvsvc service.
Error - 3/31/2011 6:52:05 PM | Computer Name = CHRISCOMPUTER | Source = System Error | ID = 1003
Description = Error code 10000050, parameter1 e1b65000, parameter2 00000000, parameter3
86ef83de, parameter4 00000001.
Error - 4/4/2011 7:43:05 PM | Computer Name = CHRISCOMPUTER | Source = Service Control Manager | ID = 7034
Description = The Linksys Updater service terminated unexpectedly. It has done
this 1 time(s).
< End of report >